#1Tools for acquiring, preserving, and analyzing digital evidence for legal or investigative purposes.
Kitploit recommended

⭐ ⭐ Distributed tcpdump for cloud native environments ⭐ ⭐

A forensic evidence collection & analysis toolkit for OS X

Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those…

Python scriptable Reverse Engineering Sandbox, a Virtual Machine instrumentation and inspection framework based on QEMU

Python module for viewing Portable Executable (PE) files in a tree-view using pefile and PyQt5. Can also be used with IDA Pro and Rekall to dump…

Threat Pursuit Virtual Machine (VM): A fully customizable, open-sourced Windows-based distribution focused on threat intelligence analysis and…

Distributed & real time digital forensics at the speed of the cloud

Tracking history of USB events on GNU/Linux

Python program to steganography files into images using the Least Significant Bit.

Dump the memory of a PPL with a userland exploit

C# wrapper for ETW that serializes kernel and user-mode event data to JSON for threat hunting, malware analysis, and incident response, with Yara…

Graph platform for Detection and Response

Read-only PowerShell module for detecting UNC2452 and other threat actor artifacts in Azure AD, auditing federated domains, service principals,…

Extract data from modern Chrome versions, including refresh tokens, cookies, saved credentials, autofill data, browsing history, and bookmarks

Easy-to-use live forensics toolbox for Linux endpoints

Open source Android Forensics app and framework

Rusty Hypervisor - Windows Kernel Blue Pill Type-2 Hypervisor in Rust (Codename: Matrix)

CLI tools for forensic investigation of Windows artifacts